Virtual Facilitation & Technology Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Virtual Facilitation & Technology flashcards as text
A CFE is investigating a romance scam conducted entirely through a social media platform's encrypted messaging feature. The suspect's account was deleted before a warrant was obtained. What is the MOST productive forensic step?
Answer: Examine the victim's device for locally cached messages and media files exchanged with the suspect
The victim's device may retain cached messages and media that were synchronized before the suspect's account deletion.
During a virtual fraud investigation involving cryptocurrency transactions, a CFE needs to trace funds across multiple wallets. Which tool type is MOST appropriate for this analysis?
Answer: Blockchain analytics platforms that map transaction flows and cluster related wallets
Blockchain analytics platforms use clustering algorithms and transaction graph analysis to trace fund flows and identify wallet owners.
A virtual facilitation session involves sharing a suspect's device screen in real time for a remote review. Which risk must be managed to maintain the forensic integrity of the review?
Answer: Remote reviewers may inadvertently influence the examiner to interact with and alter evidence on the live device
Social pressure from remote observers can lead an examiner to click, open, or move files, altering the evidence; the examiner must operate the device independently.
A CFE is reviewing metadata from a Microsoft Word document submitted as evidence of a fraudulent contract. Which metadata field MOST strongly suggests document backdating?
Answer: The 'Created' date being later than the 'Last Modified' date, or author metadata inconsistent with the claimed author
A creation date later than the modification date, or an author name that does not match the claimed signatory, is a strong indicator of document manipulation or backdating.
When facilitating a virtual training on fraud prevention for remote employees, which technology-based control is MOST effective at preventing account takeover via stolen credentials?
Answer: Implementing multi-factor authentication (MFA) on all access points
MFA requires a second verification factor beyond a password, making stolen credentials alone insufficient to access accounts.
An investigator receives a tip that a fraud scheme was coordinated using an encrypted, self-destructing messaging app. Court-ordered server data from the provider returns no messages. What is the MOST likely explanation?
Answer: The app uses end-to-end encryption with no server-side message storage, so messages never existed on the provider's servers
True end-to-end encrypted apps with ephemeral messaging store no server-side message content; plaintext data simply does not exist on the provider's infrastructure.
A CFE must testify as an expert witness about virtual meeting forensics via a remote video link. Which practice BEST preserves the credibility of the testimony?
Answer: Ensuring a controlled, distraction-free environment, stable connection, and pre-testing audio/video to prevent technical interruptions
Technical failures or distracting environments undermine witness credibility; pre-tested, controlled conditions ensure testimony is delivered professionally and without interruption.